Skip to main content
Guides Last updated: October 2026 8 min read

Captive portal or WiFi password for guest WiFi? Security compared

C
CaptiFi Editorial Team
CaptiFi · October 2026
Captive portal or WiFi password for guest WiFi? Security compared
2 layers
Encryption on the radio link, identity on the sign-in page
RFC 8110
Enhanced Open: encryption for every guest with no password
2 weeks
How often an iPhone changes its address on a portal network
6 GHz
Allows only WPA3 or Enhanced Open, never a plain open network

Venue owners often frame guest WiFi as a choice: put a password on it, or put a sign-in page in front of it. The two answer different questions. A password decides who can join the network and encrypts what they send over the air. A captive portal decides what a guest has to do before reaching the internet, and tells the venue who they are. This guide compares the two on security, convenience and what the venue learns, then sets out a configuration that gets the benefits of both.

It is written for owners and the installers who advise them, and the security claims come from the IETF standard for Enhanced Open, the Wi-Fi Alliance and Apple's documentation, listed at the end.

A password and a portal do different jobs

Job Shared password (WPA2 or WPA3 Personal) Captive portal
Keeps people off the networkAnyone without the passwordNobody; anyone can join and see the page
Encrypts traffic over the airYesNo, unless the network also uses Enhanced Open or a password
Tells the venue who connectedNoYes, whatever the page asks for
Records accepted terms and marketing consentNoYes
Limits access to paying customersOnly while the password stays privateYes, with voucher codes or paid passes
Effort for the guestFind and type the passwordComplete the page once per session

The password works at the radio layer and the portal works above it, at the web layer, so a network can have either, both or neither. The guide to WPA3 and Enhanced Open covers the encryption standards themselves in more depth.

What a shared password protects, and what it does not

A password keeps passers-by off the network and encrypts each device's traffic over the air. On a guest network, though, everyone gets the same password. It goes on a chalkboard, a table card or a receipt, it is shared with friends, and after a few weeks it is effectively public. Changing it means telling every regular and reprinting every card.

On WPA2-Personal, the shared password also limits the privacy it gives. RFC 8110 explains that with a shared key, a passive attacker who knows it can "observe the 4-way handshake and compute the traffic encryption keys" for another device. On a network where the password is printed on the wall, that is anyone in the room with the right tools. WPA3-Personal improves on this; the Wi-Fi Alliance says its users "receive increased protections from password guessing attempts". Either way, a password tells the venue nothing about who joined.

What an open network with a portal exposes

An open network has no password, so traffic between each phone and the access point is not encrypted on the radio link. In practice, most of what guests do still travels encrypted end to end, because websites and apps use HTTPS. What remains visible on a plain open network is the traffic that is not encrypted at a higher layer, such as plain HTTP pages and, on many devices, DNS lookups.

The portal does not change any of that. What it adds is a record of who joined, their accepted terms and, if they chose, their marketing consent. That is the case for an open guest network with a portal: guests get online without hunting for a password, and the venue gets a list. Enhanced Open removes most of the encryption gap.

Enhanced Open: encryption without a password

Enhanced Open is the Wi-Fi Alliance name for Opportunistic Wireless Encryption, defined in RFC 8110 in 2017. Each device agrees its own key with the access point as it joins, so traffic is encrypted over the air with nothing to type. The Wi-Fi Alliance describes it as "unauthenticated data encryption" with "no public passphrases to maintain, share, or manage". It protects against passive eavesdropping, including someone who knows the network's name and sits in the corner capturing traffic.

RFC 8110 provides "encryption of the wireless medium but no authentication", so Enhanced Open cannot prove that the access point is the venue's own, and the standard warns that it "is susceptible to an active attack in which an adversary impersonates an access point". A captive portal runs on Enhanced Open exactly as it does on an open network, and older devices that do not support it can join through transition mode where your hardware offers it. On 6 GHz, plain open networks are not allowed at all, so a guest network broadcast on the 6 GHz band of Wi-Fi 6E or Wi-Fi 7 equipment needs Enhanced Open or WPA3.

The threats that matter on guest WiFi

Threat Who it affects What helps
Someone capturing traffic over the airGuestsEnhanced Open or WPA3 on the guest network; HTTPS covers most traffic regardless
A fake hotspot with the venue's name and a lookalike sign-in pageGuestsA portal that never asks for passwords to other accounts; signage with the exact network name
One guest reaching another guest's deviceGuestsClient isolation on the guest network
A guest reaching the tills, cameras or office computersThe venueA separate staff network on its own VLAN, with its own password
One guest using all the bandwidthEveryoneA per-guest bandwidth limit and a session length
Non-customers using the WiFi from outsideThe venueVoucher codes, or a shorter session length

A shared password helps with only the first row, and only until it leaks. Most of the protection on a guest network comes from separating it from everything else and isolating guests from each other, which works whether or not there is a password.

How the choice affects returning guests

Phones identify themselves to each network with a private MAC address in place of the hardware one. Apple's guide to private Wi-Fi addresses says an iPhone chooses a Fixed address by default on networks with WPA2 or stronger security, and a Rotating one, which changes every two weeks, on networks with weak or no security. Apple's security guide adds that Rotating is the default for "OWE, WEP, captive portals, and open networks".

So adding a password to a guest network that has a portal does not keep a regular's iPhone on one address: expect it to change every two weeks either way, and the guest to be asked to sign in again after it does. For a venue with a portal this matters less than it sounds, because the guest is identified by the email address or phone number they enter, which does not change. It does explain why some regulars see the sign-in page more often than others.

A setup that covers both

Most venues are best served by two networks, configured differently.

Guest network Staff network
SecurityEnhanced Open where your hardware supports it, otherwise openWPA3-Personal, or WPA2/WPA3 where older devices need it
Captive portalYesNo
Client isolationOnOff, so staff devices and printers can reach each other
VLANIts own, with internet access onlyIts own, with access to the tills and office systems
BandwidthA per-guest limitNo limit, or a generous one
Who uses itGuestsStaff, tills, card machines, printers and venue TVs

Devices that have to sit on the guest network but cannot complete a portal, such as a TV guests cast to, can be pre-authorised by MAC address; the guide to Chromecast and smart TVs on guest WiFi covers that. Card machines belong on the staff network or their own, following your payment provider's guidance.

When a password on the guest network makes sense

A password on top of a portal can suit a small holiday let or a meeting room, where the password goes in the welcome information and the host still wants the sign-in page for terms and contact details. The trade-off is one more step for every guest, and a password that spreads beyond the people it was meant for.

The setup to avoid is a guest network with a password and no portal running alongside a portal network. Staff hand out the password because it is quicker, guests join the network with no portal, and the venue loses both the terms record and the guest list.

Running it on CaptiFi

CaptiFi's portal runs above the encryption layer, so it works the same on open, Enhanced Open and WPA2 or WPA3 guest networks; the setup guide for your hardware covers where each setting lives. In my.captifi.io you set the WiFi network name, the session length and the guest bandwidth limit for each venue under My Locations, Edit site. Bandwidth limits are not yet enforced on TP-Link Omada, Cisco Meraki or cloud-only UniFi, and a network name change is pushed only to CaptiFi devices and UniFi controllers. Guests sign in with an email address or a phone number on your branded form, and a returning device is let straight through while its address stays the same.

The hardware page lists the ten ecosystems CaptiFi runs on and the plug-and-play device for venues without compatible kit. Plans start from $69/mo on the pricing page, and you can try it on your own network with a 30-day free trial.

Sources: IETF RFC 8110, Opportunistic Wireless Encryption (March 2017); Wi-Fi Alliance, Wi-Fi security; Apple Support, Use private Wi-Fi addresses on Apple devices, and Apple Platform Security, Wi-Fi privacy with Apple devices; CaptiFi's customer documentation and its guide to WPA3 and Enhanced Open, October 2026. Wi-Fi, WPA3 and Enhanced Open are trade marks of the Wi-Fi Alliance; CaptiFi is not affiliated with or endorsed by it.

Frequently asked questions

Quick answers to the most common questions about this topic.

Is a captive portal more secure than a WiFi password?
They protect different things. A password encrypts traffic over the air and keeps people without it off the network; a captive portal records who joined and their consent but adds no encryption on an open network. For guests, Enhanced Open gives encryption without a password, and client isolation plus a separate staff network give most of the protection that matters.
Is guest WiFi with a captive portal encrypted?
Only if the network underneath is. On an open network the radio link is not encrypted, although websites and apps that use HTTPS stay encrypted end to end. On an Enhanced Open, WPA2 or WPA3 network, traffic over the air is encrypted, and the captive portal works the same way on top of it.
What is Enhanced Open and does it work with a captive portal?
Enhanced Open is the Wi-Fi Alliance name for Opportunistic Wireless Encryption, defined in RFC 8110. Each device agrees its own encryption key with the access point as it joins, with no password to type. It stops passive eavesdropping but cannot prove the access point is genuine. A captive portal runs on it exactly as it does on an open network.
Should guest WiFi have a password?
Not usually, if it has a captive portal. A shared password is soon public, adds a step for every guest and tells you nothing about who joined. Enhanced Open gives the encryption a password would, with nothing to type. A password can suit a small holiday let or a meeting room, where it goes in the welcome information.
What is client isolation on guest WiFi?
Client isolation stops devices on the same WiFi network from talking to each other, so one guest cannot reach another guest's phone or laptop. Turn it on for the guest network. It also stops phones casting to a TV on that network, which is why venue TVs that guests cast to often sit on a different network.
Can a captive portal run on a password-protected network?
Yes. The portal works above the encryption layer, so guests type the password to join and then complete the sign-in page. It suits places where the password goes only to guests, such as a holiday let, where the host still wants the sign-in page for terms and contact details.
C
Written by
CaptiFi Editorial Team

The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.

Ready to turn your guest WiFi into a marketing engine?

CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.

Related reading